Click To Chat Widget Security & Risk Analysis

wordpress.org/plugins/click-to-chat-widget

Click To Chat Widget is a WordPress plugin that allows website visitors to easily initiate a conversation with you or your team on popular messaging s …

0 active installs v1.0.0 PHP + WP 5.0+ Updated Feb 25, 2023
chatclick-to-chatmessagingwhatsapp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Click To Chat Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Click To Chat Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "click-to-chat-widget" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, and the presence of 100% properly escaped output are excellent indicators of secure coding practices. Furthermore, the lack of any file operations or external HTTP requests reduces potential attack vectors. The complete absence of any recorded vulnerabilities in its history, including critical and high severity issues, suggests a mature and well-maintained plugin. The limited attack surface, with zero entry points identified, is a significant strength. However, a notable concern is the complete absence of nonce checks and capability checks. While the current analysis shows no direct exploitability due to the lack of entry points, any future expansion of functionality or introduction of new entry points without these crucial security measures would expose the plugin to significant risks, particularly cross-site request forgery (CSRF) and unauthorized actions.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Click To Chat Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Click To Chat Widget Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Click To Chat Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
66 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped66 total outputs
Attack Surface

Click To Chat Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedincludes/class-hs-click-to-chat.php:151
actionadmin_enqueue_scriptsincludes/class-hs-click-to-chat.php:166
actionadmin_enqueue_scriptsincludes/class-hs-click-to-chat.php:167
actionadmin_menuincludes/class-hs-click-to-chat.php:168
actionadmin_initincludes/class-hs-click-to-chat.php:169
actionwp_enqueue_scriptsincludes/class-hs-click-to-chat.php:188
actionwp_enqueue_scriptsincludes/class-hs-click-to-chat.php:189
actionwp_footerincludes/class-hs-click-to-chat.php:190
Maintenance & Trust

Click To Chat Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 25, 2023
PHP min version
Downloads767

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Click To Chat Widget Developer Profile

UltiWP

4 plugins · 90 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Click To Chat Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/click-to-chat-widget/admin/css/hs-click-to-chat-admin.css/wp-content/plugins/click-to-chat-widget/admin/css/jquery-phone-validator.css/wp-content/plugins/click-to-chat-widget/admin/js/jquery-phone-validator.js/wp-content/plugins/click-to-chat-widget/admin/js/jquery-phone-validator-utils.js/wp-content/plugins/click-to-chat-widget/admin/js/hs-click-to-chat-admin.js
Script Paths
/wp-content/plugins/click-to-chat-widget/admin/js/jquery-phone-validator.js/wp-content/plugins/click-to-chat-widget/admin/js/jquery-phone-validator-utils.js/wp-content/plugins/click-to-chat-widget/admin/js/hs-click-to-chat-admin.js
Version Parameters
hs-click-to-chat-admin.css?ver=jquery-phone-validator.css?ver=jquery-phone-validator.js?ver=jquery-phone-validator-utils.js?ver=hs-click-to-chat-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
hs-click-to-chat-messagehs-click-to-chat-phone-number
Data Attributes
hs_click_to_chat_enablehs_click_to_chat_appshs_click_to_chat_messagehs_click_to_chat_phone_number
JS Globals
hs_chat_object
FAQ

Frequently Asked Questions about Click To Chat Widget